|

Ledger CTO discusses the security issues concerning the popular hardware wallet

  • Ledger suffered a data breach and had a wallet vulnerability detected a few weeks ago.
  • Ledger CTO Charles Guillemet discussed the causes and implications of these incidents. 
  • He said that the company is “most worried about phishing attempts.”

In a recent interview, Charles Guillemet, the CTO of Ledger, a popular hardware wallet provider, responded to all the project criticisms. Ledger has been subject to many difficulties in recent times. It suffered a breach in its customer contact database and a wallet vulnerability that put users’ Bitcoin at risk. 

Discussing the data breach, Guillemet said that an attacker got access to a portion of the firm’s e-commerce and marketing database through a third party’s API key that was misconfigured on their website. This allowed unauthorized access to their customers’ contact details and order information. He added that Ledger fixed the issue and disabled the troublesome API key that same day. Guillemet also noted that payment information, credentials (passwords) or cryptocurrency funds were not affected due to the breach. 

On August 5, a software vulnerability was detected in Ledger, which provided a bridge between Bitcoin and its various forks like Litecoin. Ledger issued a software update on the same day to fix the issue. In a later blog, the company reassured its users that attackers could not exploit the vulnerability to “obtain sensitive data like your private keys or recovery phrase.” 

Although Ledger’s wallets provide parameters for enhanced security, users must still be aware of the best practices to protect their assets. Guillemet explained that Ledger “is most worried about phishing attempts — emails from scammers pretending to be us.” He added that the company will never ask its users for the 24 words of their recovery phrase. 

Speaking of safeguards against malware, Guillemet said: 

Ledger devices are designed to protect users’ funds against malware on users’ computers, including fake Ledger Live applications.

Author

Rajarshi Mitra

Rajarshi Mitra

Independent Analyst

Rajarshi entered the blockchain space in 2016. He is a blockchain researcher who has worked for Blockgeeks and has done research work for several ICOs. He gets regularly invited to give talks on the blockchain technology and cryptocurrencies.

More from Rajarshi Mitra
Share:

Editor's Picks

XRP ticks up as risk-off mood, weak ETF demand cap recovery

Ripple (XRP) rebounds above $1.23 from support at $1.20 at the time of writing on Wednesday, as the broader cryptocurrency market pares losses triggered by escalating tensions in the Middle East.

Crypto Today: Bitcoin, Ethereum pare losses as XRP rebounds amid escalating tensions in the Middle East

The cryptocurrency market remains largely under pressure on Wednesday amid escalating tensions in the Middle East. After plunging from its May high of $82,823, Bitcoin (BTC) is showing signs of stabilization, consolidating above the key $67,000 support level.

Bitcoin takes a breather above $65,000 amid swelling institutional pressure

Bitcoin hovers above $67,000 as of Wednesday, taking a breather after over 6% loss the previous day. Whales are reducing their BTC holdings, likely influenced by the 12-day streak of ETF outflows.

Ondo extends gains, defying the broader market crash

ONDO extends gains on Wednesday, after rising 9% the previous day. Early access to Ondo Perps, offering 24/7 perpetual futures on US stocks, ETFs, and commodities, fuels the recovery.

Billions in ETF outflows don’t bode well
Bitcoin (BTC) remains under pressure, trading below $74,000 on Friday, and is set to post its third consecutive week of losses. The institutional sell-off continues, with spot BTC Exchange-Traded funds (ETFs) recording billions in outflows. In addition, sticky inflation and macroeconomic headwinds suppress the Crypto King’s upside potential. Institutional demand continues to weaken so far this week.